9 ms·
https://aws.amazon.com/controltower/ https://aws.amazon.com/controltower/ If we all started using Control Tower perhaps they'd get funded enough to continue to
by flyinprogrammer 4y ago
https://aws.amazon.com/controltower/ https://aws.amazon.com/controltower/
If we all started using Control Tower perhaps they'd get funded enough to continue to build it out and make it awesome.
- rcrowley 4y agoIn the meantime, check out Substrate <https://src-bin.com/substrate/ https://src-bin.com/substrate/> and don’t worry about waiting for AWS to improve.
- metadat 4y agoMr. Crowley, did you forget to mention / disclose your association and financial interest tied to this product? For context, https://www.linkedin.com/in/richarddcrowley https://www.linkedin.com/in/richarddcrowley indicates he works there.
- benatkin 4y agoIt's a bit different of a situation from the usual product recommendations because the domain of the article and link in the comment is the same.
- chronotis 4y agoSeems relevant to me. The article is from your organization, and that information is something I wouldn't have known if not for the prior commenter's comment.
- hatware 4y agoWhat a weird comment.
- abrookewood 4y agoKind of .. I think it's good that people are encouraged to disclose their interests on HN as a matter of course.
- hatware 4y agoA DM is reasonable. Calling someone out in public like that is childish.
- JimDabell 4y agoThere aren‘t any DMs on Hacker News, and if he didn’t post that comment I would have thought it was a disinterested commenter recommending something they had used, not somebody who works on the project. The cultural norm here is to disclose when you are recommending your own product and it’s not childish to point out when people fail to do that, it’s reinforcing that cultural norm.
- hatware 4y ago> There aren‘t any DMs on Hacker News Good thing they... (checks notes) ...know exactly who made the post and can reach out to them on LinkedIn or email them. Cultural norms are reinforced by good examples, there's nothing good about snippy public comments. Reaching out to them privately isn't hard, and, dare I say it: is more inclusive. I don't think I need to explain the origin of the word assume.
- Akronymus 4y ago> , there's nothing good about snippy public comments. It didn't seem snippy to me. "Why aren't you disclosing your ties" would be IMO. The message that was actually posted seemed quite diplomatic.
- hatware 4y ago> seemed quite diplomatic Turns out it is more diplomatic to reach out to someone privately first. God forbid we set a better example than the one being set.
- porker 4y agoHaving people disclose if they work for/have a vested interest in what they recommend sets HN apart from other communities. It gives me a bit more confidence that I can trust what people recommend here and isn't just hidden marketing.
- rcrowley 4y agoThe same link’s in the second sentence of the article. But, sure, I forgot.
- smcleod 4y agoFar out - that website looks dodgy as. What on earth is going on with its fonts - it looks like a newspaper vomited onto the screen.
- fazfq 4y agoIt looks completely normal to me?
- smcleod 4y agoI thought it was just on my phone, but it's goofy as on the desktop too, this is what it looks like for me in Firefox: https://imgur.com/a/o0vGIq8 https://imgur.com/a/o0vGIq8
- x86_64Ubuntu 4y agoIt looks like it's a super un-Javascripted website. It's only about 2.8MB to load when looking in Chrome Developer view.
- rcrowley 4y agoIt’s set in Computer Modern, the font Donald Knuth designed for TeX and which you most often encounter in academic papers.
- jcims 4y agoIf config can go this long with half-assed implementation I don’t see why control tower is going to fare better with more adoption. Most large enterprises are going to want to roll their own anyway.
- thedougd 4y agoThe guy or gal that's been working on it the last two years has slowly been working through my bucket list. If I can just get guardrails that configure the basic AWS security foundation stuff like password policies, I'll be satisfied. And oddly enough, the CloudFormation coverage for this stuff is abysmal. We don't even allow IAM users in the member accounts, but we really need to check off this compliance box.
- dmak 4y agoI looked at the landing page, but don't really understand when I would use this. Could you give a few examples of why this is useful?
- TYPE_FASTER 4y agoCentralized management and application of IAM policy with the goal of giving teams the freedom to manage their own account, including account security, while still protecting the organization as a whole. When customers request single tenancy in the cloud, where single tenancy is referring to an AWS account, being able to automate account management will be important when trying to scale.
- dmak 4y agoThanks!
- wrnu 4y agohttps://github.com/aws-samples/aws-secure-environment-accelerator https://github.com/aws-samples/aws-secure-environment-accele... I've used the ASEA to get a number of organizations setup. I prefer it to Control Tower (it can be installed on top of CT). The ASEA is open source and written in AWS cdk so it can be forked and modified if needed.